All research / The agenda is live: here's a sneak peek at what's waiting for you in New York

The agenda is live: here's a sneak peek at what's waiting for you in New York

New York here we come

The agenda is live: here's a sneak peek at what's waiting for you in New York

October 21, 2026. Pier Sixty. The Summit comes home.

Click Here To Register

New York is where this started. The first AI Agent Security Summit was here in 2025, back when "agentic risk" still needed a definition before you could put it on a slide. Nobody needs the definition anymore.

What's changed since we were last in this city isn't the volume of the conversation. It's the stakes. Agentic investment is on track to overtake chatbot spending by 2027. More than half of enterprises now report agents exceeding their intended scope somewhere in the lifecycle. Incidents like OpenAI's agent breaching Hugging Face didn't need a nefarious prompt or a threat actor - the agent was goal-obsessed and chained privilege escalation until the job was done. That's not a bug. It's the behavior the infrastructure was built to produce.

Meanwhile the tools that make agents useful are the same ones attackers reach for, MCP servers have settled in as the predominant attack surface, and the AI mandate comes down from leadership while deployment starts in the dev teams. Ownership got distributed whether anyone planned for it or not.

The agenda just went live. Fourteen sessions.

This is where the real conversation happens.

No vendor pitches. No fluff. Just practitioners, researchers, and security leaders who are actually breaking things, building things, and willing to be honest about both.

Here's a taste of who's up:

Yotam Perkal, Pluto Security. An MCP server is a credential with an API in front of it. In a widely used official CI MCP server, Yotam's team found a CVSS 10.0 command injection that turned a tool parameter called fileName into arbitrary code execution inside a CI pipeline, plus a CVSS 8.3 DNS rebinding flaw. Chained, the attack starts with a developer opening a webpage and ends with attacker commands running in production. Nobody had to steal a token - the server already had one and used it on the attacker's behalf.

Matheus Gutierre, ViaConnect. Your AI-powered SOC reads attacker-controlled data all day. Using an unmodified Elastic Security environment, Matheus showed that command lines, process names, and User-Agent strings become prompt injection the moment an agent treats telemetry as investigation context. Malicious activity got classified as a false positive. A malicious command got recommended to the analyst as a diagnostic procedure. Of 23 models across eight vendors, 14 were manipulated in at least one scenario. When logs are interpreted by AI, a log isn't just evidence anymore.

Vikas Malik, JPMorganChase. An agent can hold valid credentials, satisfy every IAM policy, and still execute an action the user never intended. The agent had permission - permission just stopped meaning intent. Vikas runs a live demo of the same agent with the same permissions producing two completely different outcomes under traditional IAM versus intent-aware authorization, and shows how to preserve intent across the full delegation chain without ripping out what you already have.

Sumaiya Shrabony, University of Colorado Denver. Ten autonomous agents wake her laptop at 7:55 AM, search the open web, inject what they find into their own prompts, draft outbound email, and drive her browser - all on personal credentials, none of it in any inventory. By day she runs 200+ data pipelines for 530+ users in a FERPA-regulated environment. This is a firsthand attack-surface inventory of the shadow agent population you're trying to model, presented by its operator. In her words: "I am the specimen."

Rahul Jain, Gusto. The most dangerous failure of an agent security control isn't that it's weak - it's that it never runs. Rahul demos a guardrail layer doing everything right, then adds a second plausible route to the same action that inherits none of the checks. Every unit test still passes. The control inventory is still complete. And the request goes through. Test the paths, not the controls.

That's five of fourteen. The rest of the program runs from OWASP's capability control matrix and a four-layer agentic detection model through cross-agent privilege escalation in Google's ADK, MCP tool poisoning, sandbox escapes that never touch the sandbox, and the attack surface of a 34,000-star autonomous pipeline.

This community has been ahead of the curve every time. Copilot attack surfaces before vendors acknowledged them. Agentic risk before most people had a name for it.

New York started that. Time to pick it back up.

See the full agenda and grab your spot at zenity.io/resources/events/ai-agent-security-summit-nyc